Exposed secret literal
Critical
- Finding
- File appears to expose a hardcoded API secret or token.
Security checks across static analysis, malware telemetry, and agentic risk
No artifact-backed suspicious behavior could be confirmed because the workspace artifacts were not readable in this run.
Treat this as an inconclusive low-confidence pass, not substantive approval. Re-run the review with readable metadata.json and artifact files before installing or publishing the skill.
1
VirusTotal findings are pending for this skill version.
No visible risk-analysis findings were reported for this release.